cbcvebase.
CVE-2022-49260
published 2025-02-26

CVE-2022-49260: In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - fix the aead software fallback for engine Due to the subreq pointer…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.64%
47.4th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - fix the aead software fallback for engine Due to the subreq pointer misuse the private context memory. The aead soft crypto occasionally casues the OS panic as setting the 64K page. Here is fix it.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 6c46a3297beae4ae2d22b26da5e091f058381c7c < 40dba7c26e897c637e91312b35f664f1d4d0073c40dba7c26e897c637e91312b35f664f1d4d0073c
linuxlinux>= 6c46a3297beae4ae2d22b26da5e091f058381c7c < ef7b10f3cac7810ddcfd976304fd125aca33d144ef7b10f3cac7810ddcfd976304fd125aca33d144
linuxlinux>= 6c46a3297beae4ae2d22b26da5e091f058381c7c < 5c1149e2abe0b7489300736b8277b45b113de67f5c1149e2abe0b7489300736b8277b45b113de67f
linuxlinux>= 6c46a3297beae4ae2d22b26da5e091f058381c7c < 0a2a464f863187f97e96ebc6384c052cafd4a54c0a2a464f863187f97e96ebc6384c052cafd4a54c
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 5.14 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.